This governance framework will provide a sustainable structure which can evolve to meet and address the reality of cyber security in Trinidad and Tobago. The proposed organisational structure for the TTCSA has been developed and is attached as Appendix I. 5.2 Incident Management In order to secure and strengthen the country’s critical information infrastructure, coordinated efforts should be made to mitigate, and/or control incidents in the quickest and most efficient manner. There is therefore a requirement for an organization which can serve as the national focal point for incident reporting, incident management and incident response. The GoRTT will establish a Trinidad and Tobago Computer Security Incident Response Team (TT-CSIRT) which will be responsible for: e dissemination of cyber security information; e technical guidance and support in the event of a cyber-incident; e collaboration between and among government entities at the national level, the private sector, academia, and the international CSIRT community. TT-CSIRT would possess the capabilities to: e Provide warning of potential threats, incidents, and attacks; e Facilitate information-sharing among the TT-CSIRT constituency relating to best practices, investigative information, coordination of incident response, and incident management procedures and processes; e Analyse cyber vulnerabilities, incidents, and attack methodologies; e Provide technical assistance to the GoRTT and other stakeholders within the national framework; e Conduct investigations, and forensics analysis; 15

Select target paragraph3